Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

17.0.1.181 0.03%
16.0.3.51 14.21%
16.0.2.32 11.91%
16.0.1.18 10.86%
16.0.0.282 33.27%
15.0.6.14 17.51%
15.0.5.109 1.90%
15.0.4.53 4.83%
15.0.3.37 0.15%
15.0.2.72 1.53%
15.0.1.13 0.93%
15.0.0.198 0.40%
12.0.1.669 0.03%
12.0.1.652 0.15%
12.0.1.647 0.65%
12.0.1.633 0.28%
12.0.1.609 0.15%
12.0.1.600 0.03%
12.0.0.756 0.03%
12.0.0.614 0.03%
12.0.0.343 0.03%
12.0.0.301 0.23%
12.0.0.297 0.03%
11.0.0.674 0.13%
11.0.0.663 0.03%
View more

Relationships

Parent processes
Child process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegEnumKeyExA, RegCreateKeyExA, RegQueryInfoKeyA, RegEnumKeyA, RegDeleteKeyA, RegQueryValueA, RegDeleteValueA, RegOpenKeyA, RegOpenKeyExA, RegQueryValueExA, RegCloseKey, RegCreateKeyA, RegSetValueA, RegSetValueExA, RegCreateKeyW, RegSetValueW, RegOpenKeyW, RegQueryValueW
gdi32.dll
GetDeviceCaps
kernel32.dll
GetEnvironmentVariableA, GetProcAddress, LoadLibraryA, GetModuleHandleA, GetTickCount, InterlockedIncrement, InterlockedDecrement, FreeLibrary, QueryPerformanceCounter, QueryPerformanceFrequency, GetVersionExA, CreateFileA, FindClose, CreateDirectoryA, MoveFileA, GetSystemInfo, GetVersion, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, GetModuleHandleExA, GetCurrentThreadId, RaiseException, Sleep, FindFirstFileW, GetModuleFileNameA, GetCurrentProcessId, SizeofResource, LockResource, LoadResource, FindResourceA, FindResourceExA, SetCurrentDirectoryA, GetCurrentDirectoryA, IsBadWritePtr, VirtualProtect, IsBadReadPtr, SetUnhandledExceptionFilter, TerminateThread, CreateThread, GetCurrentProcess, WriteFile, GetThreadContext, VirtualQuery, OpenProcess, SetFilePointer, GlobalMemoryStatus, UnmapViewOfFile, MapViewOfFile, CreateFileMappingA, GetSystemTimeAsFileTime, IsDebuggerPresent, UnhandledExceptionFilter, TerminateProcess, GetStartupInfoA, InterlockedCompareExchange, InterlockedExchange, GetProcessHeap, HeapSize, HeapReAlloc, HeapFree, HeapAlloc, HeapDestroy, SetEnvironmentVariableA, GetCommandLineW, WideCharToMultiByte, GetLastError, DeleteFileA, CreateMutexA, ReleaseMutex, CloseHandle, OpenMutexA, WaitForSingleObject, SetErrorMode, SetEvent, ResetEvent, CreateEventA, FindResourceW, FindResourceExW, lstrlenW, MultiByteToWideChar, GetStartupInfoW, HeapSetInformation, DecodePointer, EncodePointer, InitializeCriticalSectionAndSpinCount, lstrlenA, ExitProcess, GlobalAddAtomA, GlobalDeleteAtom
msvcp100.dll
DllMain
msvcp71.dll
DllMain
msvcp90.dll
DllMain
msvcr100.dll
DllMain
msvcr71.dll
DllMain
msvcr90.dll
DllMain
ole32.dll
OleInitialize, OleUninitialize
pncrt.dll
strrchr, strstr, _controlfp, _except_handler3, __set_app_type, __p__fmode, __p__commode, _adjust_fdiv, _putenv, _initterm, __getmainargs, __setusermatherr, printf, _assert, sprintf, getenv, _purecall, memmove, strchr, exit, _acmdln, __dllonexit, _onexit, _exit, _XcptFilter
shell32.dll
SHGetFolderPathA, SHGetFolderPathW, SHCreateDirectoryExW, SHCreateDirectoryExA
shlwapi.dll
PathAddBackslashA, PathAppendA, PathAppendW, PathAddBackslashW
user32.dll
GetDC, ReleaseDC, RegisterWindowMessageA, RegisterClassExA, GetClassInfoExA, CreateWindowExA, DefWindowProcA, PostThreadMessageA, DestroyWindow, UnregisterClassA, CharPrevA, CharNextA, GetSystemMetrics, SetMessageQueue, EnumWindows, GetPropA, SendMessageA
version.dll
VerQueryValueA, GetFileVersionInfoA

REALPLAY.exe

RealPlayer (32-bit) by RealNetworks (Signed)

Remove REALPLAY.exe
Version:   16.0.0.282
MD5:   01243fa89fbec041e873de8386138440
SHA1:   118f225e23e365e7b5cc01be2dc40146cd52d473
SHA256:   7a9f1b4d4c295eae8cd8cc1805cb0df57e71d3411351c735cf425eb3dfa3bb40

What is REALPLAY.exe?

RealPlayer, by RealNetworks, is a cross-platform software product primarily used for the playing of recorded media. The media player is compatible with numerous formats within the multimedia realm, including MP3, MPEG-4, QuickTime, Windows Media, and multiple versions (proprietary) of RealAudio and RealVideo formats. The software is powered by an underlying open source media engine called Helix.

About REALPLAY.exe (from RealNetworks)

Real brings you RealPlayer, the only solution you’ll need for managing all your music and videos. It’s the best free media player around for enjoying all types of entertainment! You can also transfer

DetailsDetails

File name:realplay.exe
Publisher:RealNetworks, Inc.
Product name:RealPlayer (32-bit)
Description:RealPlayer
Typical file path:C:\Program Files\real\realplayer\\realplay.exe
File version:16.0.0.282
Size:489.15 KB (500,888 bytes)
Certificate
Issued to:RealNetworks
Authority (CA):Thawte
Expiration date:Tuesday, August 16, 2011
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 9.0
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
RealNetworks, Inc.
27% remove
RealPlayer is a cross-platform software product primarily used for the playing of recorded media. The media player is compatible with numerous formats within the multimedia realm, including MP3, MPEG-4, QuickTime, Windows Media, and multiple versions of RealAudio and RealVideo formats. The software is powered by an underlying open source media engine called Helix.

BehaviorsBehaviors

Autoplay handlers
Runs under the registry key 'SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers'
  • Handler name 'RPPlayMediaOnArrival'
  • Handler name 'RPPlayDVDMovieOnArrival'
  • Handler name 'RPPlayCDAudioOnArrival'
  • Handler name 'RPDVDBurningOnArrival'
  • Handler name 'RPCDBurningOnArrival'
Scheduled tasks
  • The job 'RealCreateProcessScheduledTask1247296S-1-5-21-3669111873-1580353433-1935662099-1000' runs on registration in the path '\RealCreateProcessScheduledTask1247296S-1-5-21-3669111873-1580353433-1935662099-1000'
  • The task '{E26C2663-BEC4-4819-8D2D-15D312F1158A}' runs on registration in the path '\{E26C2663-BEC4-4819-8D2D-15D312F1158A}'
  • The job '{CD1D82FD-6C85-4BFE-9A55-66B729011AF4}' runs on registration in the path '\{CD1D82FD-6C85-4BFE-9A55-66B729011AF4}'
  • The task '{2D57B953-5798-4027-AD32-FB96E7FE4673}' runs on registration in the path '\{2D57B953-5798-4027-AD32-FB96E7FE4673}'
  • The task '{CAF98FFB-8246-4180-8543-CE4146F5E2AE}' runs on registration in the path '\{CAF98FFB-8246-4180-8543-CE4146F5E2AE}'
  • The task '{B815BF93-A61B-4EED-9AF4-402B5BA00560}' runs on registration in the path '\{B815BF93-A61B-4EED-9AF4-402B5BA00560}'
  • The job '{B00723DD-88CF-42AB-9272-85A4ACE0FC8B}' runs on registration in the path '\{B00723DD-88CF-42AB-9272-85A4ACE0FC8B}'
  • The job '{A5338D06-1807-4121-B5B0-69E6C2003821}' runs on registration in the path '\{A5338D06-1807-4121-B5B0-69E6C2003821}'
  • The task '{0895B815-A511-4D0A-B56A-6CF1E9D08C22}' runs on registration in the path '\{0895B815-A511-4D0A-B56A-6CF1E9D08C22}'
  • The job 'RealCreateProcessScheduledTask11318824S-1-5-21-1478862715-1088129902-3265764659-1000' runs on registration in the path '\RealCreateProcessScheduledTask11318824S-1-5-21-1478862715-1088129902-3265764659-1000'
  • The task '{AA7C5070-83A8-43BC-AF3F-225C1AC0CA71}' runs on registration in the path '\{AA7C5070-83A8-43BC-AF3F-225C1AC0CA71}'
  • The job '{A894CEF0-8569-4479-8ED4-3BFB4E6FB838}' runs on registration in the path '\{A894CEF0-8569-4479-8ED4-3BFB4E6FB838}'
  • The task '{471C618E-7BF8-43F7-B4A1-C55025E0F927}' runs on registration in the path '\{471C618E-7BF8-43F7-B4A1-C55025E0F927}'
  • The task '{D9F1E4D5-8621-48ED-B124-22C258F32FF6}' runs on registration in the path '\{D9F1E4D5-8621-48ED-B124-22C258F32FF6}'
  • The job '{4D69A9E0-ABF9-4C34-BF05-F5F743F30350}' runs on registration in the path '\{4D69A9E0-ABF9-4C34-BF05-F5F743F30350}'
  • The task '{07044237-9D30-413D-B8FB-35F47E7B82FA}' runs on registration in the path '\{07044237-9D30-413D-B8FB-35F47E7B82FA}'
  • The job '{ED98A541-D106-4B62-A208-5156B2F9CF19}' runs on registration in the path '\{ED98A541-D106-4B62-A208-5156B2F9CF19}'
  • The task '{DA53DD74-4B9B-49E2-9B64-F6FC940B430A}' runs on registration in the path '\{DA53DD74-4B9B-49E2-9B64-F6FC940B430A}'
  • The job '{788FD8F4-7015-4AF1-85D0-A2BFB1568852}' runs on registration in the path '\{788FD8F4-7015-4AF1-85D0-A2BFB1568852}'
  • The job '{6A797CBD-F1A4-464C-A6C7-F6A33CAEFB18}' runs on registration in the path '\{6A797CBD-F1A4-464C-A6C7-F6A33CAEFB18}'
  • The job '{502CA4E6-C85D-4FC7-A5BC-AE15D4F9FDEC}' runs on registration in the path '\{502CA4E6-C85D-4FC7-A5BC-AE15D4F9FDEC}'
  • The task '{3864C674-88EC-438C-805E-B5940EC59B79}' runs on registration in the path '\{3864C674-88EC-438C-805E-B5940EC59B79}'
Windows firewall allowed programs
Exceptions allow programs to access to the Internet through an outbound connections
  • Firewall exception for 'C:\Program Files\Real\RealPlayer\realplay.exe'
Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'RealTray' → C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
Network connections
Access through an approved Windows firewall exception
  • [TCP] v-5-327-d2928-214.webazilla.com (78.140.187.214:80)
  • [TCP] channel-ecmp-13-prn1.facebook.com (69.171.235.16:443)
  • [UDP] listens on port 64359
  • [UDP] listens on port 49200
  • [UDP] listens on port 55226
  • [UDP] listens on port 64636

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.01328444%
    0.028634%
    Kernel CPU:0.00395922%
    0.013761%
    User CPU:0.00932523%
    0.014873%
    Kernel CPU time:5,634,952 ms/min
    100,923,805ms/min
    CPU cycles:1,134,004/sec
    17,470,203/sec
    Context switches:679/sec
    284/sec
    Memory
    Private memory:92.56 MB
    21.59 MB
    Private (maximum):72.95 MB
    Private (minimum):34.64 MB
    Non-paged memory:92.56 MB
    21.59 MB
    Virtual memory:345.62 MB
    140.96 MB
    Virtual memory (peak):364.55 MB
    169.69 MB
    Working set:58.52 MB
    18.61 MB
    Working set (peak):91.03 MB
    37.95 MB
    Page faults:487,359/min
    2,039/min
    I/O
    I/O read transfer:784.02 KB/sec
    1.02 MB/min
    I/O read operations:616/sec
    343/min
    I/O write transfer:9.07 KB/sec
    274.99 KB/min
    I/O write operations:13/sec
    227/min
    I/O other transfer:8.67 KB/sec
    448.09 KB/min
    I/O other operations:285/sec
    1,671/min
    Resource allocations
    Threads:41
    12
    Handles:782
    600
    GUI GDI count:212
    103
    GUI GDI peak:165
    142
    GUI USER count:279
    49
    GUI USER peak:240
    71

    BehaviorsProcess properties

    Integrety level:Medium
    Platform:32-bit
    Command lines:
    • "C:\Program Files\real\realplayer\\realplay.exe" /runevent "C:\Program Files\real\realplayer\update\upgr3270.dll" autoupdateevent
    • "C:\Program Files\real\realplayer\realplay.exe" /launcC:start_menu
    • "C:\Program Files\real\realplayer\realplay.exe" "/commanC:mylibrary(navigatetopath)"
    • "C:\Program Files\real\realplayer\\realplay.exe" "C:\????\.rm"
    • "C:\Program Files\real\realplayer\realplay.exe" /launcC:desktop
    Owner:User
    Parent processes:

    ResourcesThreads

    Averages
     
    realplay.exe (main module)
    Total CPU:0.99073995%
    0.272967%
    Kernel CPU:0.23608327%
    0.107585%
    User CPU:0.75465668%
    0.165382%
    CPU cycles:25,016,551/sec
    5,741,424/sec
    Context switches:254/sec
    79/sec
    Memory:804 KB
    1.16 MB
    msvcrt.dll (Windows NT CRT DLL by Microsoft)
    Total CPU:0.65156933%
    Kernel CPU:0.04915452%
    User CPU:0.60241481%
    CPU cycles:11,598,671/sec
    Memory:688 KB
    flash32_11_5_502_146.ocx (Shockwave Flash by Adobe Systems)
    Total CPU:0.48485611%
    Kernel CPU:0.00890346%
    User CPU:0.47595266%
    CPU cycles:8,696,898/sec
    Context switches:14/sec
    Memory:14.77 MB
    mshtml.dll (Windows Internet Explorer by Microsoft)
    Total CPU:0.33304001%
    Kernel CPU:0.06893852%
    User CPU:0.26410149%
    CPU cycles:6,400,803/sec
    Memory:11.77 MB
    ntdll.dll
    Total CPU:0.28812098%
    Kernel CPU:0.22489303%
    User CPU:0.06322795%
    CPU cycles:5,347,322/sec
    Memory:1.23 MB
    WININET.dll
    Total CPU:0.11826114%
    Kernel CPU:0.07696360%
    User CPU:0.04129754%
    CPU cycles:1,978,675/sec
    Memory:1.11 MB
    rpflashplayer.dll (RealPlayer (32-bit) by RealNetworks)
    Total CPU:0.09282699%
    Kernel CPU:0.03766892%
    User CPU:0.05515807%
    CPU cycles:8,528,100/sec
    Memory:216 KB
    flash32_11_6_602_171.ocx (Shockwave Flash by Adobe Systems)
    Total CPU:0.00973219%
    Kernel CPU:0.00181928%
    User CPU:0.00791291%
    CPU cycles:1,426,780/sec
    Memory:14.91 MB
    MSVCR100.dll
    Total CPU:0.00827968%
    Kernel CPU:0.00380597%
    User CPU:0.00447371%
    CPU cycles:825,180/sec
    Context switches:15/sec
    Memory:764 KB
    rjbdll.dll (RealNetworks RealPlayer by RealNetworks)
    Total CPU:0.00793342%
    Kernel CPU:0.00396671%
    User CPU:0.00396671%
    CPU cycles:297,246/sec
    Memory:2.05 MB
    wow64cpu.dll
    Total CPU:0.00416747%
    Kernel CPU:0.00018522%
    User CPU:0.00398225%
    CPU cycles:120,510/sec
    Memory:32 KB
    mswsock.dll
    Total CPU:0.00375474%
    Kernel CPU:0.00375474%
    User CPU:0.00000000%
    CPU cycles:20,302/sec
    Memory:240 KB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 7 Home Premium 54.50%
    Windows 7 Ultimate 27.50%
    Windows 8.1 8.00%
    Microsoft Windows XP 5.00%
    Windows 8 Enterprise N 5.00%

    Distribution by countryDistribution by country

    United States installs about 50.50% of RealPlayer (32-bit) .

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Toshiba 23.53%
    Hewlett-Packard 19.61%
    Dell 18.82%
    Sony 15.69%
    Acer 7.84%
    Intel 7.84%
    Lenovo 4.71%
    GIGABYTE 1.96%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE